PT0-002 Attacks and Exploits Practice Question
During a web application test, the tester discovers a parameter that reflects user input in the response without sanitization. Which type of vulnerability is most likely present?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reflected XSS
Reflected XSS occurs when user input is immediately reflected in the response without proper encoding or sanitization.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DOM-based XSS
Why it's wrong here
DOM-based XSS is incorrect because the vulnerability occurs entirely client-side in the browser's JavaScript environment, where attacker-controlled data flows from a source like location.search or document.referrer to a sink such as innerHTML or document.write, never being included in the server's HTTP response. Since the parameter value is found echoed directly in the server response, the attack vector is not a DOM manipulation issue, but a server-side reflection of input.
- ✗
Stored XSS
Why it's wrong here
Stored XSS is incorrect because the payload would need to be persisted on the server, for example in a database, message board, or log file, and then delivered to other users when that stored data is later retrieved and rendered. In this case, the tester's parameter is reflected immediately in the current response without any indication that it is saved server-side or displayed to other users later, which is the defining characteristic of reflected, not stored, XSS.
- ✗
SQL injection
Why it's wrong here
SQL injection is incorrect because it targets the database layer by injecting malicious SQL syntax into queries, typically resulting in authentication bypass, data leakage, or database errors. The direct echo of the parameter into the HTML response demonstrates a lack of output encoding in the web application layer, not a flaw in SQL query construction, and there is no evidence that the parameter influences a database query or generates database-driven responses.
- ✓
Reflected XSS
Why this is correct
Reflected XSS is correct because the tester's parameter value is immediately included in the server's HTTP response without proper output encoding, creating a non-persistent vulnerability. An attacker can craft a malicious URL that, when clicked, causes the victim's browser to execute the injected script in the context of the application's origin. The immediate echo back in the response exactly matches the definition of reflected XSS, distinguishing it from stored XSS, which involves server-side persistence, and DOM-based XSS, which never involves the server response.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.